> It's most likely coming from a stack trace generated by your application.
> The JavaMail API is vulnerable to header injection via the Subject header,
> and you're probably seeing that phenomenon (though by accident).
>
> For my own application, I wrote a subclass of SMTPAppender that truncates
> the Subject header at the first EOL character, which prevents this issue
> from occurring.
>
>

Thanks, I figured it was something like this, but I didn't realize the
problem with the subject line. Would this be appropriate to file as a JIRA
issue?

jason


-- 
Jason Bennett, [email protected]
E pur si muove!
Get Firefox! - http://getfirefox.com
_______________________________________________
Logback-user mailing list
[email protected]
http://mailman.qos.ch/mailman/listinfo/logback-user

Reply via email to